← Case Files · The Breach Files
Accellion FTA, 2021: the rehearsal for MOVEit
- People affected
- Dozens of organisations; the Washington State Auditor alone reported 1.6 million individuals
- When it happened
- Mid-December 2020 – January 2021
- Made public
- January 2021
- How they got in
- Chained zero-day vulnerabilities in Accellion's File Transfer Appliance, a legacy product approaching end of life
- Attributed to
- Cl0p, working with the group tracked as FIN11
- What it cost
- Accellion settled a consolidated class action for $8.1 million in 2022; victim organisations bore their own costs
What was exposed: Personal and financial records · Medical records · Regulatory filings · Legal documents · Government and central bank data
Two and a half years before the MOVEit campaign put ninety million people's data on a leak site, the same criminal group ran the same attack against a different file transfer product and proved it worked. Almost nobody outside security noticed, which is why it happened again twice.
What happened
Accellion's File Transfer Appliance was a product with a long history. Organisations bought it to send sensitive files to external parties with encryption, access control and an audit trail — the kind of software that ends up holding payroll records, medical files, legal discovery and regulatory submissions, because that is exactly what it is for.
By 2020 the product was around twenty years old. Accellion had a newer platform, had been encouraging customers to migrate, and had set end of life for April 2021.
In mid-December 2020, attackers began exploiting a chain of previously unknown vulnerabilities in the appliance. The chain allowed unauthenticated access, execution of commands on the appliance, and installation of a web shell — a small piece of code giving persistent remote control. From there the attackers inventoried the files the appliance held and took them.
Accellion issued patches within days of learning of each flaw. Further vulnerabilities in the same product surfaced in January as researchers and attackers both examined it more closely. Customers were patching against a moving target on a product they had already been told to stop using.
The end-of-life window is a predictable attack window. When a vendor announces a product's retirement, three things happen at once: engineering attention moves to the replacement, the remaining customer base is exactly those organisations least able to move quickly, and the announcement itself tells attackers which software is about to stop being defended. Attacking a product during its final year is close to optimal, and Accellion is the clearest demonstration of that logic being applied deliberately.
Extortion without encryption
Cl0p did not deploy ransomware. It took files and threatened to publish them, listing victims on a leak site and releasing samples for organisations that did not engage.
That model is now the dominant one, and Accellion is where it was validated at scale. Encryption is loud, triggers alarms, and can be defeated by good backups. Exfiltration is quiet, and there is no backup that protects against publication. A victim can restore every system perfectly and still be facing the same demand — which changes the negotiation completely.
Who it reached
- Reserve Bank of New Zealand — A central bank, which commissioned and published an unusually frank independent review of its own failures afterwards.
- Australian Securities and Investments Commission — The corporate regulator, exposed through the appliance used for credit licence applications.
- Washington State Auditor's Office — Around 1.6 million individuals' unemployment claim data, including Social Security numbers and bank details.
- Health Net, Flagstar Bank, Kroger, Shell, Bombardier, the University of Colorado, Jones Day — Insurers, banks, retailers, manufacturers, universities and law firms, with no shared characteristic except the product.
The Reserve Bank of New Zealand review is worth singling out. It found that the bank had treated the appliance as a self-contained system, had not fully understood what data was accumulating on it, and had not acted on the vendor's migration advice with sufficient urgency. Regulators being publicly honest about their own incidents is rare and disproportionately useful.
The timeline
- Mid-December 2020 — Exploitation of the first zero-day begins; Accellion patches within days.
- January 2021 — Further vulnerabilities in the appliance are found and patched; victims begin disclosing.
- February 2021 — Cl0p starts publishing stolen data and naming victims; the Washington State Auditor notifies 1.6 million people.
- April 2021 — The File Transfer Appliance reaches its scheduled end of life.
- August 2021 — The Reserve Bank of New Zealand publishes its independent review.
- 2022 — Accellion settles a consolidated class action for $8.1 million.
- 2023 — Cl0p runs the same playbook against Fortra GoAnywhere in February and MOVEit in May.
What it changed
Not enough, which is the point of including it. The Accellion campaign established the target class, the technique and the extortion model in full public view. Two years later MOVEit produced a far larger version of the same event. The industry's collective response to a warning shot is the actual lesson here.
File transfer products started getting inventoried. Security teams that did the work after Accellion generally found more of these appliances than they expected, holding more data than anyone intended, going back further than anyone had realised.
Data retention on transfer systems became a control. The single most effective mitigation among victims was the least technical: not having years of completed transfers still sitting there. A transfer product that retains everything is a warehouse pretending to be a pipe.
End-of-life notices got read as risk notices. Vendor retirement dates moved from procurement paperwork into risk registers, with the deadline treated as a hard security boundary rather than a commercial suggestion.
What to take from it
- Find out where your organisation sends large files externally. The answer is usually more systems than the official one, and the unofficial ones are the unpatched ones.
- Delete completed transfers on a schedule. Data you no longer hold cannot be taken, and nothing else you do will match that for effectiveness.
- Treat an end-of-life announcement as a countdown on a security control. The last year of a product's life is when it is least defended and most targeted.
- If you were notified by an organisation you deal with, the exposure depends on what they sent through it. Payroll, claims and benefits files are unusually complete records of a person — name, address, date of birth, national ID and bank details in a single row.
Questions people ask
What is a file transfer appliance and why does it matter?
It is a server whose job is to move large, sensitive files between organisations — payroll to a bureau, claims to an insurer, evidence to a law firm. That makes it internet-facing by design and full of concentrated sensitive data by design, and it sits at the boundary between organisations so one compromise yields many parties' data. It is structurally the highest-leverage target class in enterprise software, and attackers worked that out before most defenders did.
How is this connected to the MOVEit breach?
Same crew, same playbook, two years earlier. Cl0p exploited Accellion FTA in December 2020, Fortra GoAnywhere in early 2023, and MOVEit in May 2023. Each time: a zero-day in managed file transfer software, mass automated exploitation, data theft rather than encryption, and extortion through a leak site. Accellion is where the model was proven.
Was the software out of date?
The File Transfer Appliance was roughly twenty years old and Accellion had been actively encouraging customers to migrate to its newer platform, with end of life scheduled for April 2021. The attack landed in the window between the vendor saying stop using this and customers actually stopping. That window is where a great deal of damage happens, because migration projects are slow and the deadline always feels soft until it is not.
Who was affected?
Among those who confirmed it publicly: the Reserve Bank of New Zealand, the Australian Securities and Investments Commission, the Washington State Auditor's Office, Kroger, Shell, Bombardier, the University of Colorado, Flagstar Bank, Health Net and the law firm Jones Day. The common factor was the appliance, not the sector — which is what makes supply chain incidents so hard to reason about in advance.
Sources
- Mandiant — Cyber Criminals Exploit Accellion FTA for Data Theft and Extortion — the technical analysis of the exploit chain
- Reserve Bank of New Zealand — independent review of the Accellion breach, August 2021 — unusually candid post-incident report
- Washington State Auditor's Office breach notification, February 2021
- In re Accellion Inc. Data Breach Litigation, N.D. Cal. — $8.1 million settlement, 2022
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.